Cross-Site Request Forgery Vulnerability in PingFederate Administrative Console
CVE-2025-32736
4.9MEDIUM
What is CVE-2025-32736?
The Administrative Console of PingFederate versions prior to 13.1 is susceptible to Cross-Site Request Forgery (CSRF) attacks. Malicious actors could exploit this vulnerability by using specially crafted links that can trigger unauthorized actions when clicked by logged-in administrators. This issue emphasizes the need for robust CSRF protection and vigilance in managing administrative sessions to prevent potential security breaches.
Affected Version(s)
PingFederate Windows 10.0 < 13.1
